fix: settle 0.x memory hardening and security backlog - #139
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
Verification evidence is now committed in docs/security-quality-follow-up.md and the corrected draft assessment. Original-head hosted CI, C#/JS CodeQL and fuzz all passed; uploaded CodeQL records had 0 results and empty errors/warnings (C# resolved 283 references, unresolved 0). Downloaded hosted fuzz artifacts show 370,328 inputs in 61 seconds, features 3,191→22,137, corpus 4→1,706; the separate crash probe succeeded and no genuine campaign findings were emitted. Isolated merged Core/Tools coverage measured 85.37% line / 73.69% branch, not whole-repository coverage. After the documentation update, local unit/live-SQL acceptance passed again: 439 / 464 successful tests, 0 failures, four existing skips; CLI validation, format, npm/readme/version checks and the official MCP stdio smoke passed. Waiting for the latest-head checks before merge, then inspecting fresh main Scorecard before alert disposition. External badge review/submission remains #140; independent human review and maintenance history are not fabricated. |
Authorized scope
Maintainer requests reachable PR/issue and security/quality settlement, explicitly continuing 0.x only. No 1.x release is authorized. Oh My Pi/OpenCode production success is recorded as user-reported evidence, not invented 30-day or other-harness certification.
Fixes #55
Fixes #56
Fixes #52
Implementation
Observed local acceptance
Settlement gate
Inspect the hosted CI, CodeQL and fuzz executions before merge; inspect Scorecard on merged main before any alert disposition. Then close the six original dependency PRs as incorporated/superseded by this PR, with evidence links. Remaining genuine human/external prerequisites stay visible. Details: docs/security-quality-follow-up.md.